• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

akrennmair / newsbeuter / 959 / 4
60%
master: 60%

Build:
DEFAULT BRANCH: master
Ran 17 Aug 2017 08:54PM UTC
Files 130
Run time 11s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

17 Aug 2017 06:06PM UTC coverage: 34.506% (-0.03%) from 34.531%
COMPILER=clang++-3.6 GCOV=/usr/bin/gcov

push

travis-ci

Minoru
Sanitize inputs to bookmark-cmd (#591)

Newsbeuter didn't properly shell-escape the arguments passed to
bookmarking command, which allows a remote attacker to perform remote
code execution by crafting an RSS item whose title and/or URL contain
something interpretable by the shell (most notably subshell
invocations.)

This has been reported by Jeriko One <jeriko.one@gmx.us>, complete with
PoC and a patch.

This vulnerability was assigned CVE-2017-12904.

4148 of 12021 relevant lines covered (34.51%)

141.99 hits per line

Source Files on job 959.4 (COMPILER=clang++-3.6 GCOV=/usr/bin/gcov)
  • Tree
  • List 0
  • Changed 4
  • Source Changed 1
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Build 959
  • Travis Job 959.4
  • 96e9506a on github
  • Prev Job for COMPILER=clang++-3.6 GCOV=/usr/bin/gcov on master (#958.4)
  • Next Job for COMPILER=clang++-3.6 GCOV=/usr/bin/gcov on master (#967.4)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc